PoolParty is a collection of process injection techniques targeting Windows Thread Pools. It was originally researched and released by SafeBreach Labs, including a C++ proof-of-concept, and later reimplemented in C# as the red-team tool SharpParty by Stroz Friedberg/LevelBlue. The technique works by crafting and inserting legitimate-looking work items into a target process’s thread pool to execute injected code, rather than relying on more commonly monitored methods such as CreateRemoteThread. The content states that PoolParty was designed to evade endpoint detection and response systems and that SafeBreach reported bypassing five leading EDR vendors. It targets Windows systems and is associated in the content with offensive security research and red-team tradecraft rather than a named threat actor. Reported delivery and execution methods for the C# implementation include inline MSBuild tasks executed by msbuild.exe and reflective in-memory loading via PowerShell. In one described engagement, encrypted SharpParty code was embedded in an MSBuild Task XML, used HTTP keying to retrieve and validate a decryption key, and ultimately delivered a Cobalt Strike beacon; persistence was tested via a registry Run key. The content also states that Microsoft Defender for Endpoint initially failed to detect the technique, that Microsoft validated a bypass report in March 2025 and later added detections, and that other EDR products may now detect it based on suspicious msbuild.exe usage and process injection behavior. High-confidence indicators and artifacts mentioned in the content include use of Windows Thread Pool injection, msbuild.exe, PowerShell reflective assembly loading, registry Run key persistence, and delivery of a Cobalt Strike beacon.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collection of Windows thread-pool-based process injection techniques intended to evade EDR; reimplemented in C# as 'SharpParty' to enable use in tooling (including inline MSBuild task execution).
A suite of Windows Thread Pool–based process injection techniques that inject code by crafting and inserting legitimate thread-pool work items into a target process, using the work item’s trigger/conditions as the execution primitive (avoiding common indicators like CreateRemoteThread).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.